Effective 1 October 2026 · Version 2026-10-01

Data-retention statement

The SchoolBus retention schedule and the deletion controls used for the service.

CategoryRetention
Raw phone GPS points30 days by default; a School Admin may set 1–90 days
Completed-trip route/stop coordinatesRedacted after 90 days; technical setting is 30–90 days
Notification delivery history90 days; technical setting is 30–90 days
Inactive push installationsRemoved after 90 days; revoked immediately when access ends
Student, Guardian, and staff operational profilesWhile active; delete or anonymize within 90 days after the relationship ends, subject to reviewed obligations
Accounts with an in-app deletion requestAccount and linked personal data deleted or anonymized within 30 days of the request, subject to an active hold or reviewed obligation
Security and administrative audit logs12 months and designed without raw coordinates or unnecessary child information
Encrypted backupsNo more than 35 days
Irreversibly aggregated statisticsMay be retained when no school user, child, bus run, or pickup point can be identified

Automated deletion and redaction

Retention jobs calculate fixed cutoffs, delete eligible location, heartbeat, delivery/provider, and inactive-installation records, redact old trip coordinates, and append category-level deletion evidence. A failed job rolls back its data changes. An authorized School Admin can pause scheduled deletion for their school; while it is paused, these jobs do not run for that school, and records past their period are deleted or redacted when it is resumed.

Holds and backups

An authorized School Admin may create a narrowly identified, reasoned hold with an expiry no more than one year away. Holds do not silently permit indefinite raw-location retention. Deleted production data may remain only until encrypted backups expire, no later than 35 days.

Contact [email protected] with a retention or deletion question. Effective date: 1 October 2026.